This Week in Spring. July 28th, 2026 – Josh LongThis Week in Spring - July 28th, 2026Hi Spring fans! Welcome to another installment of This Week in Spring! The title says in Spring, but here in the northern hemisphere, it's clearly the middle of summer. Hot! I'm sitting here on my laptop on a warm... Continue Reading →
VMware
ValleyRAT distribution campaign targeting…
ValleyRAT distribution campaign targeting organizations in JapanValleyRAT distribution campaign targeting...As reported by the researchers from Cato Networks, the Monarch threat group (aka SilverFox) has recently launched a malicious campaign targeting a Japanese industrial manufacturing company to deliver ValleyRAT, a persistent remote access trojan. Initiated via invoice-themed phishing [...]Broadcom Social Media Advocacy
Flying Eagle Android RAT Source Code Leak Fuels…
Flying Eagle Android RAT Source Code Leak Fuels New AttacksFlying Eagle Android RAT Source Code Leak Fuels...Researchers at Hunt.io and NetAskari recently reported a new malware family known as the Flying Eagle Android RAT, which has fueled a fractured cybercriminal ecosystem following its source code leak. Threat actors have deployed over 170 active servers running... Continue Reading →
Malicious npm Packages Target Chinese-Speaking…
Malicious npm Packages Target Chinese-Speaking EngineersMalicious npm Packages Target Chinese-Speaking...In a recent write-up, Socket details a complex supply chain attack utilizing a cluster of fraudulent npm packages to distribute a cross-platform remote access trojan. The threat actors uploaded counterfeit unscoped modules designed to impersonate proprietary Alibaba Group [...]Broadcom Social Media Advocacy
How to Replace VCF Automation Certificate
How to Replace VCF Automation Certificate | Tomas FojtaHow to Replace VCF Automation CertificateIn an Enterprise or Cloud Provider scenario the VCF Automation (VCFA) certificate should be signed by a public Certificate Authority and will need to be rotated yearly. If the VCFA is fronted by an external load balancing the same certificate must be... Continue Reading →
VMware Cloud Foundation APIs: Configure…
VMware Cloud Foundation APIs: Configure Certificate Authorities | #vExpert Gary J. BlakeVMware Cloud Foundation APIs: Configure...A key fleet management capability delivered by VMware Cloud Foundation is the ability to centrally manage certificates across all the components of your platform, the process involves first configuring VCF Operations to interact with either a Microsoft or an OpenSSL... Continue Reading →
Resetting the admin@local Password on the…
Resetting the admin@local Password on the VMware Cloud Foundation 9 Installer | Learn how to reset the admin@local password on the VMware Cloud Foundation 9 Installer with a safe operational runbook, validation steps, and rollback guidance. #vExpert Paul BryantResetting the admin@local Password on the...Learn how to reset the admin@local password on the VMware Cloud Foundation... Continue Reading →
Refreshing an Existing vSAN Cluster with New…
Refreshing an Existing vSAN Cluster with New ServersRefreshing an Existing vSAN Cluster with New...Refreshing hardware is an inevitable task of lifecycle management in a data center. Existing vSAN clusters may have servers that are nearing the end of life by the manufacturer, or simply may no longer meet the technical requirements of an organization. The... Continue Reading →
vSphere 8.0 Update 3k Fixes Critical CVEs—but…
vSphere 8.0 Update 3k Fixes Critical CVEs—but Temporarily Blocks the VCF 9.1 Upgrade Path | #vExpert Piotr TarnawskivSphere 8.0 Update 3k Fixes Critical CVEs—but...Broadcom released VMware vSphere 8.0 Update 3k on 29 July 2026, delivering critical security fixes for both vCenter Server and ESXi. Normally, the recommendation would be straightforward: review the release notes, validate... Continue Reading →
VMSP Toolkit 2.0 — Assurance Edition
VMSP Toolkit 2.0 — Assurance Edition. #vExpert Tommy GrotVMSP Toolkit 2.0 — Assurance EditionMost compliance tooling shows you the first number. The second number is the reason to trust the first one. A requirement the appliance cannot answer is returned as Not_Reviewed, never inferred, never quietly counted as a pass. [...]Broadcom Social Media Advocacy